Confirm a Direct Debit Authorization OTP
HSBC Hong Kong only. When your payer banks with HSBC, the bank texts them a one-time password. Send the code they enter here with otp.id from the latest response. A correct code usually completes the authorization at once (SUCCEEDED, plus the webhook); otherwise it is SUBMITTED until the bank confirms. A wrong code leaves the authorization as it is and returns attemptsRemaining; after 3 wrong codes, regenerate the OTP. An OTP is valid for 100 seconds.
Authorization
authorization Set Your Secret API Key
In: header
Path Parameters
Header Parameters
A unique value, eg. a UUID.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
The code your payer received by SMS.
^[A-Za-z0-9]+$0 <= length <= 10otp.id from the latest Direct Debit Authorization response. It changes each time the OTP is regenerated.
^[A-Za-z0-9]+$0 <= length <= 10Response Body
*/*
application/json
*/*
application/json
curl -X POST "https://example.com/v1/direct-debit-authorizations/string/otp-confirmation" \
-H "Content-Type: application/json" \
-d '{
"otpId": "IAF",
"otpCode": "123456"
}'The bank accepted the code and the authorization is active.
{
"id": "dda_0KAQCK2Y8FNTB",
"billReferenceNumber": "A0012334455",
"payerSwiftBic": "HSBCHKHHHKH",
"payerBankCode": "004",
"payerSegment": null,
"payerName": "Wong Ka Ming",
"payerBankAccountNumber": "511123456888",
"payerIdHash": null,
"payerIdType": null,
"status": "SUCCEEDED",
"failureReason": null,
"underlyingErrorMessage": null,
"startDate": "2026-10-05",
"precheckMinAmount": 0,
"precheckMaxAmount": 1000000,
"precheckCurrency": "HKD",
"maxAmount": null,
"maxAmountCurrency": null,
"payerAuthorizedMaxAmount": 0,
"endDate": null,
"authorizeUrl": null,
"cancelUrl": null,
"returnUrl": null,
"cancelReturnUrl": null,
"transactionReference": "D261005J2344",
"createdAt": "2026-10-05T04:00:00.000000Z",
"updatedAt": "2026-10-05T04:01:12.000000Z"
}